HN user

arielcostas

607 karma
Posts0
Comments164
View on HN
No posts found.

The thing is, in many cases the provider selling internet to you isn't the same as whoever owns the cables that arrive to your place. So you may switch between providers (which in Spain are owned by 4 groups: MasOrange, Movistar/Telefónica, Vodafone and DIGI) but in many cases your IP goes through Telefónica's network (either by hiring them, or via NEBA, basically renting their infra) or MasOrange (they acquired a lot of local companies like R in Galicia, Euskaltel in the Basque Country, Telecable, and many others, including Orange) and basically own 14 brands as of now [^1].

So even if you do switch providers, chances are you are using one of the same (if not the actual same) provider, and got perhaps other options in those 4 groups. There's an actual coverage map by our Ministry for Digital Transformation[^2] that shows what actual coverage there is. Sometimes there's "Aire Networks" or others, but mostly it's the four large groups I mentioned before.

[^1]: https://masorange.es/en/brands/ [^2]: https://experience.arcgis.com/experience/275e90e49dc544ef94e...

Yeah, I'll let a company I don't do business with dictate who I actually do business with just because of their money interests. I don't like or use Cloudflare, I believe they are not good for the internet due to how centralised everything gets on them, and their blocking of non-mainstream setups (browser, OS, Javascript, no VPNs, no Tor and so on); but I'm not letting a football company say "we don't care about screwing you, we are blocking this"

We can call it "abuse of market position" then. The United States' Federal Trade Commission[^1] sued Amazon in 2023 with this pretext.

In Germany, the Federal Cartel Office fined Amazon[^2] 59 million euro (68.7 millions US dollars) because of "abuse of market power" with anti-competitive practices.

The European Commission[^3] also opened an investigation regarding Amazon's practices regarding Prime and the "Buy Box" (I had to look this up, apparently it means being picked as the default seller for a product where multiple sellers are offering it), since you need to pay extra for FBA to have your products marked as Prime (appearing before on the search results, and being the "buy box") and Amazon itself competes with you sometimes, being both a marketplace and a seller.

[1] https://www.ftc.gov/news-events/news/press-releases/2023/09/... [2]: https://www.politico.eu/article/german-regulator-fines-amazo... [3]: https://ec.europa.eu/commission/presscorner/detail/en/ip_20_...

It’s just yet another centralized service

Yeah, collaboration usually requires some sort of centralisation. Whether that is the LKML+git.kernel.org, gitlab.gnome.org, salsa.debian.org or Sourcehut, or GitHub. At least Sourcehut isn't completely proprietary and shoving AI down your throat at every possible chance. The same can be said for Codeberg and almost any GitLab CE, Gitea or Forgejo instance

Do you also dislike the concept of requiring to be a certain age to say enter a strip club or a sex club?

You can't compare someone checking your document before entering a strip club (or even a pub, or asking for alcoholic drinks) vs a computer system getting and logging an attestation and verifying it against a government database (or third party) where the Govt knows who the credential belongs to, and who's checking it. Along with my government "compelling me" to run software (even if it's open source itself) that requires me to have a binding contract with a foreign third-party company known for privacy violations, and running their proprietary software stack on my device for said government software to work, so I can participate in most parts of the digital society.

Of course the existing "identity verification" done by scanning yourself and your ID document (passport, national ID or driving licence) is not acceptable, unless counted exceptions where said documentation is needed (banking and others, because of KYC/AML)

Migrating to the EU 4 months ago

What do you miss about Google Maps in OSM? Just business information (schedules, contact info, reviews...), or something else?

Google allows you to use TXT to verify though, since this "feature" of disabling domains because of Safe Search is based only on web contents (A/AAAA/CNAME) they could disable those and allow TXT anyway since those are AFAIK harmless

The problem is "markets can stay irrational longer than you can stay solvent". It doesn't matter when the bubble pops if the governments (especially the US') bail those companies out.

The damage is already being done, whether you are a 401k/IRA holder with a position on the S&P 500 way too overweighted by the Mag7&co and their circular dealings, or just needing to buy computer parts way over their market value because some companies are over-leveraging to outcompete you for that hardware (or electricity), or even at a smaller scale by increasing software costs because everything is "AI-powered" now and of course you wouldn't want only "deterministic" software that just works and doesn't have a slop machine integrated.

Bunny Database 6 months ago

It's not about it being hard, it's about delegating. Many companies are a bit less sensitive to pricing and would rather pay monthly for someone else to keep their database up, rather than spending engineering hours on setting up a database, tuning it, updating it, checking its backups, monitoring it and making it scale if needed.

Sure, any regular SME can just install Postgres or MySQL without even setting much up except with `mysql_secure_install`, a user with a password and an 'app' database. But you may end up with 10-20 database installs you need to back up, patch and so on every once in a while. And companies value that.

End-to-end usually means only the data's owner (aka the customer) holds the keys needed. The term most used across password managers and similar tools is "zero knowledge encryption", where only you know the password to a vault, needed to decrypt it.

There's a "data encryption key", encrypted with a hash derived of your username+master password, and that data encryption key is used locally to decrypt the items of your vault. Even if everything is stored remotely, unless the provider got your raw master password (usually, a hash of that is used as the "password" for authentication), your information is totally safe.

A whole other topic is communications, but we're talking decryption keys here

It's not. Regulation (EC) No 1370/2007[^1] states in the annex, related to compensation in cases where a public operator operates subsidised public services and commercial, for-profit activities, that:

In order to increase transparency and avoid cross-subsidies, where a public service operator not only operates compensated services subject to public transport service obligations, but also engages in other activities, the accounts of the said public services must be separated so as to meet at least the following conditions: [...]

Another topic is: should France be allowed to keep the TGV monopoly in their country because they need it to finance the rest of their network, while they are allowed to operate abroad (like in Spain), taking away business from Renfe through the free market competition they try to impede on their country anyway?

[^1]: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...

Every government in Spain for the last decade or more has been cutting corners in maintaining the rail networks: high speed (where this accident happened), the conventional network and commuter rail. You failed to mention the fact our budget has been extended since 2023, that the actual track where this happened was given maintenance under a year ago (per the minister, [^1]) and the train that first derailed (Iryo's ETR1000) was last checked 4 days ago.

Regarding the former Minister (Ábalos), he's awaiting trial and not yet convicted (even though, IMHO he is probably guilty), and he hasn't been in the ministry since 2021[^2] so it makes no sense to bring it up when he has been out for nearly 4.5 years now.

[^1]: https://www.lavozdegalicia.es/noticia/espana/2026/01/18/osca... [^2]: https://www.elconfidencialdigital.com/articulo/otros/jose-lu...

On the other hand, it may end up the other way: pressure you or bully you into quitting yourself. Here in Spain it happens sometimes: firing you is expensive and they don't want you around for whatever issue, so they'll try to find any justification to fire you, or just pressure you in some way on another to make you miserable enough to quit. No doubt that would happen in the US.

Yes. At least in 11 Pro installs, you can just say you'll be joining to a domain, create a local admin account and never actually join it. Then to create other users you can do it via the command line, or probably through the GUI after telling it you don't want one a couple of times

But enterprises may negotiate not to use (and pay) Copilot, can't they? Or go with another provider if it's such a big deal. Plus it being enabled by default in every VS Code (I haven't checked this, last I remember you need to sign in with GitHub) gets you on the free tier where you make zero revenue for Microsoft and some expense (not too much, probably).

You can fetch a user's PGP public key via their HKPS endpoint, for example https://mail-api.proton.me/pks/lookup?op=get&search=username.... The one who apparently doesn't support PGP at all is Tuta.

Ideally, you'd be able to provide the service your key directly (you can do it in Sourcehut for example, IIRC), and they use that key without relying on a third-party server. Maybe using something like WebFinger could be a solution too, for automatic key discovery from a "trusted" party (the recipient's email server).

Wait until you see Azure. Apparently you need to create either an "Azure OpenAI" or a "Microsoft Foundry", where AFAIK (got an email last week) Foundry now includes everything AI including "Azure OpenAI", the former "Cognitive Services" (for speech, computer vision and other stuff) and inference on non-OpenAI models. But wait, because once you create that, you are told to go to another portal (ai.azure.com) where you get an "old" foundry experience and anew one that can't be enabled for every project. Oh, wait, did I mention there apparently used to be a "Foundry" and a "Foundry Project"? Oh, and all those apparently work with a single API key, unless (I guess) you set up authentication with the Azure SDK, which makes you go back to Azure Portal (or maybe Entra ID?).

All of that while trying to explain to your non-technical boss how he can browse the voices available at "the Azure thingy" to pick his favourites to then pick and use in the project due relatively soon. Since, of course, you told him the original Cognitive Speech Services (or Speech Services, or Cognitive Services-Speech, or whatever they decided to call it on that specific page) semi-public URL where he could browse the gallery was "speech.microsoft.com" which is now semi-dead with awful loading times that seem some server issue and has been happenning for a few months now. Or tell them to go to the "new foundry" where he might not be able to find the resource or might not have stuff in the regions you were using up until then, or whatever crap this 3.56 trillion-dollar company decides to throw at you to prevent you from using their services.

And all of this is the exploration phase, where you just use the GUIs and copy things around until they work. Then you need to figure out what you did (and more importantly, where) to be able to write some Terraform/OpenTofu or Bicep or similars to try and keep the environment replicable to avoid the excruciating pain of repeating every single step you followed to get it on a working state.

At the very least, Google was nice enough to launch Vertex AI inside GCP for enterprises that have figured that out, and then Google AI Studio as an almost completely separate thing that only is bound to Google Cloud for billing purposes, similar to how Firebase is integrated too.